Impact
A flaw in the Centralized Thirdparty Jars component with network access via HTTP allows an unauthenticated attacker to fully compromise the application. The vulnerability permits bypassing authentication and gaining unrestricted control, potentially tampering with or redirecting the security services that protect other Fusion Middleware products. Because the flaw includes a scope change, exploitation can also impact additional connected products beyond the Platform Security for Java.
Affected Systems
The vulnerability affects Oracle Platform Security for Java 12.2.1.4.0 and 14.1.2.0. These are the only officially supported versions impacted, and attackers can target them via HTTP without authentication.
Risk and Exploitability
The CVSS score of 10.0 indicates maximum severity for confidentiality, integrity, and availability. The EPSS score is less than 1%, suggesting a very low probability of real-world exploitation at the time of this analysis, and it is not listed in the CISA KEV catalog. The likely attack vector is a network-based HTTP request that does not require authentication, making it easily exploitable. Due to the scope change, successful exploitation of this takeover flaw could also affect other connected services.
OpenCVE Enrichment